DCSIMG
Install WSUS 3.0 - Step-By-Step - The Security Wizard

The Security Wizard

Fighting for the good guys...

על הבלוג

Windows Live Alerts


Security Related Resources

Install WSUS 3.0 - Step-By-Step

I've managed to compose a quick installation procedure for those of you who want to utilize the great free utility from microsoft...

Enjoy!

Pre-Requisites

  1. IIS 6.0 with ASP.net installed (windows Components).
    go to control panel à add/remove programs à Windows Components


    check application server and click details.

    make sure that application server console and ASP.net are check and then check Internet Information Services and click Details.

    make sure that BITS, Common files, Internet Information Services Manager, and then click world wide web service and click details:

    make sure that Active server pages and world wide web service are check and click OK twice and click next.

    Click Finish.
  2. MMC 3.0 (no need if win2003 sp2 exists).
  3. .net framework 2.0 (exists as part of windows server R2 or available for download from Microsoft at http://www.microsoft.com/downloads/details.aspx?FamilyID=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5)
  4. Microsoft Report Viewer Setup (available for download from Microsoft at http://www.microsoft.com/downloads/details.aspx?familyid=8a166cac-758d-45c8-b637-dd7726e61367)



Wsus3.0 Installation

Install Wsus 3.0 from location: http://www.microsoft.com/downloads/details.aspx?FamilyId=E4A868D7-A820-46A0-B4DB-ED6AA4A336D9



Check I Accept and then click next.

Check the Store updates locally and type D:\Wsus (or any other folder. Recommended not to use your system partition for storing WSUS updates) on the path to save the updates. Then click next.

Chose Install Use and Existing server Database on this computer and leave the path on default (same location as WSUS update). Then click next.

Click Next.


Check "Use existing IIS Default Web Site" and click next.





WSUS Configuration Wizard

After the setup ends, the following screen will open up:

Click Next.

Check the I would like to join box and click Next.

Choose synchronize from Microsoft update, and click next.

In case you have a proxy server on you organization specify proxy settings, else leave all settings at default and click next. It is recommended to set the WSUS to work without a proxy server and allow it a direct connection to the internet (open the appropriate ports on the FW).


In the connect to upstream server page, click start connecting. After the server has finished the initial sync, the next button will be available. Click next.

In the choose language window, choose English and Hebrew (or any other language of your choice) and click next.

On the choose products page, check the products you wish to sync (default, windows – all version, office – all versions, Exchange – all versions). Then click next.

On the choose classifications page, choose all classifications and click next.

On the sync schedule page, choose synchronize automatically when first sync is at 12:00:00AM and the sync per day setting is set to 24. Then click next.

On the finished page, check both checkboxes and click finish.

WSUS initial configuration

On the Update service administrator console that opens when the setup ends, click options and on the options tab. On the options window, click automatic approvals.

On the automatic approval window, check the default automatic approval rule (automaticly approves critical and security updates) and click new rule if you wish to add additional auto-approve rules for specific products or classifications.

On the add rule wizard specify any other auto approve rules that you wish by product or classification.

On the choose product window, check only forefront-forefront client security and click ok.

Back on the add rule window under step 3, type rule name (ex. FCS Update rule) and click ok twice.

Defining WSUS Update Policy (GPO)

Open Group Policy Management Console (GPMC). Start -> Run -> write gpmc.msc -> OK.

Right click on the Group policy objects container and click new.

Write the policy name and click OK.

Expand the group policy objects container and then right-click the object you have just created and click edit.

Expand the Computer configuration -> Administrative Templates -> Windows Components -> Windows Update.

Now configure the following options:

  1. Configure Automatic Updates
  2. On the specify internet Microsoft update service location, enter the netbios name that your internal clients will need to address when connecting to the wsus server.

Recommended settings

  1. Client Side targeting Specifies the target group name or names that should be used to receive updates from an intranet Microsoft update service.
    If the status is set to Enabled, the specified target group information is sent to the intranet Microsoft update service which uses it to determine which updates should be deployed to this computer.
    note: in order for this to work, you need to create groups in the WSUS server.
  2. Reschedule automatic updates scheduled installations Specifies the amount of time for Automatic Updates to wait, following system startup, before proceeding with a scheduled installation that was missed previously.
    If the status is set to Enabled, a scheduled installation that did not take place earlier will occur the specified number of minutes after the computer is next started.
  3. No auto-restart Specifies that to complete a scheduled installation, Automatic Updates will wait for the computer to be restarted by any user who is logged on, instead of causing the computer to restart automatically.
    If the status is set to Enabled, Automatic Updates will not restart a computer automatically during a scheduled installation if a user is logged in to the computer. Instead, Automatic Updates will notify the user to restart the computer.
  4. Automatic updates detection frequency Specifies the hours that Windows will use to determine how long to wait before checking for available updates. The exact wait time is determined by using the hours specified here minus zero to twenty percent of the hours specified. For example, if this policy is used to specify a 20 hour detection frequency, then all clients to which this policy is applied will check for updates anywhere between 16 and 20 hours.
    If the status is set to Enabled, Windows will check for available updates at the specified interval.
    If the status is set to Disabled or Not Configured, Windows will check for available updates at the default interval of 22 hours.
  5. Allow automatic updates immediate installation Specifies whether Automatic Updates should automatically install certain updates that neither interrupt Windows services nor restart Windows.
    If the status is set to Enabled, Automatic Updates will immediately install these updates once they are downloaded and ready to install.
  6. Allow non-administrators to receive update notifications pecifies whether, when logged on, non-administrative users will receive update notifications based on the configuration settings for Automatic Updates. If Automatic Updates is configured, by policy or locally, to notify the user either before downloading or only before installation, these notifications will be offered to any non-administrator who logs onto the computer.
    If the status is set to Enabled, Automatic Updates will include non-administrators when determining which logged-on user should receive notification.

After finished configuring the GPO, go back to the GPMC console and link the GPO to the OU that contains the computer objects you wish to work with the WSUS server. Do this by right clicking the OU and choosing link an existing GPO.

פורסם: Sep 23 2007, 06:25 PM by yanivf | with 40 comment(s) |
תגים:,

תוכן התגובה

Install and setup Windows Xp, Firewall, WSUS 3.0, iSCSI and WinPE From USB | Install, setup and configure כתב/ה:

Pingback from  Install and setup Windows Xp, Firewall, WSUS 3.0, iSCSI and WinPE From USB | Install, setup and configure

# October 21, 2007 4:42 AM

cyberst0rm כתב/ה:

Excellent article - One of the most well written, easy to understand WSUS setup guides I have ever come across!

Well done!

cyberst0rm's tech blog

http://cyberst0rm.blogspot.com

# November 12, 2007 4:16 PM

Mahaveerdoss כתב/ה:

Excellent

# December 24, 2007 7:22 PM

It's VISTASTIC כתב/ה:

Awesome.. this tutorial is just what I was looking for and helped me setup WSUS 3.0 at our local organization.

# February 21, 2008 6:20 AM

Mon כתב/ה:

Excellent

This is really helpful.

Keep on going.

# May 6, 2008 8:21 AM

Maggit כתב/ה:

very good mate - helped me out big time !!! thanks

# June 13, 2008 5:49 PM

Martin כתב/ה:

I am installing on another clients site but does anyone no why when i have installed the app and configured it etc i cannot see the pc's in the computer section? there added as delegates in the GPO so i take it they should be found ? ? ? ? if you could help me out a little that would be great

cheers

# June 20, 2008 2:06 PM

Cristina כתב/ה:

Thanks.. this make my life so easy in deploying my Forefront.!

I wish ur my side, so I can kiss you.

# July 29, 2008 11:09 AM

d כתב/ה:

Thanks a bunch. Very helpful and efficient. Send a link to Microsoft so they can create quick guides similar to yours:).

Shabbat Shalom:)

# July 30, 2008 2:51 PM

Paparux כתב/ה:

HI can i have 2 WSUS in my infrasctructure one for all Windows , SQL etc updates to be dowloaded and await installation and have another wsus server just for forefront for download and imediate installation?

# August 1, 2008 12:26 PM

Lucky כתב/ה:

I cannot find wsusadmin anywhere in the default web site location under IIS. Can anyone help?

# August 12, 2008 2:12 PM

johnnie כתב/ה:

does automaic updates have to be turned on in order for it all to work right

# September 10, 2008 12:49 PM

Kannan כתב/ה:

I followed the same step described above but my clients are not showing in the WSUS Console

Please Help me

Kannan .S

# September 16, 2008 10:43 AM

7eg@z כתב/ה:

well done

# October 7, 2008 3:41 PM

NAVEED כתב/ה:

I followed the same step described above but my clients are not showing in the WSUS Console

Does this WSUS really work or it is just a waste of struggle........

IT NEVER WORKS.........

# November 26, 2008 9:12 AM

Lorenzo כתב/ה:

When it comes to Step-By-Step instructions for product installations, it doesn't get any better than this!

# December 10, 2008 2:05 PM

adrianadukerzrgn כתב/ה:

Неплохой проэкт:))

www.liveinternet.ru/.../post94873727

# January 27, 2009 8:24 PM

ermoas כתב/ה:

now this is what i call a step by step tutorial! thanks a lot! =)

# February 4, 2009 4:23 AM

Lacsap כתב/ה:

Thank you very much. Everithing is working now.

# February 6, 2009 11:47 PM

Inds כתב/ה:

Please check and download full WSUS 3.0 SP1 configuration step by step.

-Inds

# April 21, 2009 7:59 AM

Inds כתב/ה:

forums.techarena.in/attachment.php

Download full cofiguration.

# April 21, 2009 8:02 AM

Talent Jr. כתב/ה:

Finally!!! A visual tutorial of what we have been taught in the class! Thank you!!!!!

# May 10, 2009 1:51 PM

Musab Mustafa כתב/ה:

Excelent,

thnx alot..

# June 13, 2009 4:20 PM

Leo Robertson כתב/ה:

Thank you very much. Everithing is working now.

# June 25, 2009 12:20 PM

Jojo כתב/ה:

Excellent article.

# July 22, 2009 6:20 AM

Configuring WSUS « craiggumbley.co.uk כתב/ה:

Pingback from  Configuring WSUS «  craiggumbley.co.uk

# November 2, 2009 2:02 PM

kirtan כתב/ה:

thanks

kirtan

# November 11, 2009 8:54 AM

Murtuza כתב/ה:

Brilliant!!

just brilliant.  Thank you very much for your help.

# December 23, 2009 11:23 AM

satish כתב/ה:

thanks for helping , i need a some help

i had 100 systems ,10 systems are in local domain and other computers are out side the domain, i need to send updates to all the systems ,

please suggest me for further proceeding ...

Thanks

satish

# January 15, 2010 9:07 PM

WSUS 3.0 Install and Configuration - Zytel KB כתב/ה:

Pingback from  WSUS 3.0 Install and Configuration - Zytel KB

# January 29, 2010 7:55 AM

JohnnyCash כתב/ה:

Hi there.

Thank you for a great post. It was very helpfull.

Anyone reading this post should bookmark this guys contents.

I have a new PC and needed some installation help so i went over to http://www.InstallSoftware.com but they did not provide me with the in depth

info this guy did. he kicks all the bigger sites' butts.

Thanks Again

# February 1, 2010 2:14 AM

Touqeer כתב/ה:

Very Nice

# February 13, 2010 10:08 AM

qwdqwdq כתב/ה:

dqwdqwdwqd

# February 18, 2010 5:55 AM

The Head כתב/ה:

Hi,

If you are having problems with your clients not showing in the WSUS Console please follow these steps. Please note these steps will only work if you are working in an organisation where the clients have all been cloned.

Go to the client machine and do the following.

1. Start - Run - and type in net stop wuauserv

2. Start - Run - and type in regedit

3.Click on HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate then delete the SusClientId

then click on Auto Update and locate and delete the following keys: LastWaitTimeout, DetectionStartTime, NextDetectionTime. Once these are all deleted close all windows and do the next step.

4. Start - Run - and type in net start wuauserv

I find it helps giving the machine a reboot.

Then return to your WSUS Console and refresh and the clients should start showing up, i have found that sometimes they appear straight away but other times they may take a few minutes.

Good Luck

# February 25, 2010 4:52 PM

zeeshan כתב/ה:

Hi!

i'm installing wsus but it's giving me this message at the the end..

"There is a problem with this windows installer package. a program run as part of the setup did not finish as expected."

Plz help!!

# March 17, 2010 6:40 AM

Step By Step WSUS Installation « Rega's Blog כתב/ה:

Pingback from  Step By Step WSUS Installation « Rega's Blog

# May 6, 2010 6:25 AM

vivek.V כתב/ה:

Thanks

# September 5, 2010 11:21 AM

configure WSUS 3.0 | Nag's space כתב/ה:

Pingback from  configure WSUS 3.0 | Nag's space

# February 14, 2011 3:57 PM

amit כתב/ה:

I am deploying forefront Endpoint protection  i have created automatic approval rule will it work without appying group policy  

# June 29, 2011 6:49 AM

Step By Step WSUS Installation | Regabond post כתב/ה:

Pingback from  Step By Step WSUS Installation | Regabond post

# June 30, 2011 5:16 PM
שלח תגובה

(שדה חובה)  

(שדה חובה)  

(אופציונלי)

(שדה חובה) 

Please add 6 and 2 and type the answer here:


Enter the numbers above: